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(54) Abstract Ttle 

Management system and method for monitoring stress in a network 

(57) A raw data value for a monitored cliaracterlstic of a network device or link is obtained by the network 
management system and compared with a predetermined threshold value for the monitored characteristic. If 
the raw data value Is greater than or equal to the threshold value, the management system provides a stress 
value equal to a default value which is a maximum or minimum of a predefined bounded range; if the raw data 
value is less than the threshold value the management system cateulates a stress value within the bounded 
range using an appropriate algorithm. Thus raw data is normalised to a predetermined range for example zero 
to 100 for ease of interpretation by the network manager. Stress values for a plurality of monitored 
characteristics may be combined to form a single aggregated stress value for the network. 
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MANAGEMENT SYSTEM AND 
METHOD FOR MONITORING STOESS 
IN A NETWORK 

5 

The present invention relates to the management of a communications system or 
networic, and more particularfy to the monitoring of ''stress" in a network. 

The following description is concerned with a data communications system such 
10 as a local area networic (LAN), that is an Ethernet network. However, the skilled person 
will appreciate that the present invention will have more general applicability to other 
types of managed networks including wireless networks. 

A local area network (LAN) typically comprises a plurality of computers, 
15 compxiter systems, workstations and other electronic devices connected together by a 
common media such as twisted pair or coaxial cable or fibre optic cable. Data can be 
communicated between devices on the netwoik by means of data packets (or frames) in 
accordance a predefined protocol 

20 Computers and other de^aces connected to a networie can be managed or 

unmanaged devices. A managed device has processing capability vAnch enables it inter 
cdia to monitor data traffic sent fi^m, received at, and passing through the ports of the 
device. Monitored data associated with the ports of the networie device is stored in 
memory on the network device. Unmanaged devices do not have this processing 

25 capability. 

It is becoming increasingly common and necessary for an individual to be 
appointed to manage a network. The appointed networie manager (or administrator) 
utilises a network management station which inchides network management hardware and 
30 software. In particular, the network management station is able to access management 
data from managed network devices using an appropriate management protocol (e.g. the 



SNMP protocol) and display this data for use by the network manager. 

Known network management systems simply read the management data from the 
managed network devices and present this data to the network manager, typicaUy in the 
form of numeric text, substanliaUy michanged. The network manager is expected to 
interpret the data in managing the network. 



One of the important tasks of a network manager is to assess the operational 
performance of the various network devices and links as well as the network as a whole. 
The netwoik manager needs to know wh«i problems are arising within the network and 
which particular network devices are responsible for such problems etc. 

Typical problems which may affect the performance of a networic inchide: 

1. slow operating speed of the network, and individual network devices, 
leading to slow movement of data traffic across the network, indicated by e.g. slow 
response time for a given network device; 

2. vohimes of data traffic on the network due to e.g. over- utilisation of 
the network links, networic devices and the network as a whole; and 

3. high error rates in the transmission of data packets across the network, 
indicated by e.g. the loss of data packets in a networic device and errors in received data 
padcets. 



The aforementioned problems whidi occur in the operation of a network 
contribute to the poor "health" of a network The concept of the health of a networic is 
wen known in the field of network management. In the present description, however, it 
is more convenient to refer to the "stress" of a networic (or network device or link) rather 
than its "health". It will be understood that a high level of stress equates to a low level 
of health and vice versa. Although the present invention is described as monitoring stress 
in a network, it will be appreciated that the present invention is equally applicable to 
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momtoring health in a network. 

Problems which affect the performance of a network, and therefore contribute to 
the level of "stress", may be of greater or lesser significance. For instance, a problem 

5 with the operating speed of an end station may be less significant than a problem with the 
operatmg speed of a central core device such as a switch. Thus, the level of stress of a 
network depends upon a number of factors including device type, network media type and 
the type of problem occurring. The networic manager must take all such factors into 
accoimt when interpreting the management data received from the managed network 

10 devices to establish whetha- the performance of the network is satisfectory. 

It would be desirable for a network management system to monitor characteristics 
of network devices and links which are indicative of problems occurring in a network 
which contribute to "stress", (such characteristics are referred to herein as "metrics") and 

IS provide data to the networic manager mdicative of the level of stress which is easy to 
interpret It would fiirther be desirable to determine a value indicating the overall 
performance of each network object (a "network object" is defined herein as a network 
device or link) on a network and/or the overall performance of parts of, or all o^ the 
networic, so that the network manager woxild not be required to interpret the monitored 

20 data, but could immediately ascertain the performance ofthe network (or part of the 
network) fi:om the value provided by the network management system. 

In accordance with a first aspect, the present invention provides a method for 
processing data representing monitored characteristics in a network comprising network 
25 devices and links to provide a stress value representing the performance of the network 
or a part thereof, the method comprising: 

obtaining a raw value of data for a monitored characteristic of a network device 

or link; 

comparing said raw value with a predetermined threshold value for said monitored 
30 characteristic; 
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if said raw data value is greater than or equal to said threshold value, providing 
a stress value equal to a default value, said default value being a maximum or minimum 
value of a predefined bounded range; and 

if said raw value is less than said threshold value, calculating a stress value within 
5 said predefined bounded range using an ^propriate algorithm for said monitored 
characteristic. 

In accordance with a second aspect, the present invention provides a computer 
readable mediimi having a computer program for carrying out the method of the first 
1 0 aspect of the present invention. 

In accordance with a third aspect the present invention provides network 
management apparatus for processing data representing monitored characteristics in a 
netwoiic comprising networic devices and links to provide a stress value representing the 
1 5 performance of the network, the apparatus comprising: 

a network connection or port for receiving a raw value of data for a monitored 
characteristic of a network device or link; 

a processor for comparing said raw value with a predetermined threshold value 
for said monitored characteristic obtained fl-om memory; and if the conq)arison determines 
20 that raw data vahie is greater than or equal to said threshold value, providing a stress 
value equal to a de&uk value, said defeult value being a maximum or mttitmnn^ value of 
a predefined bounded range; and if the comparison determines that said raw value is less 
than said threshold value, calculating a stress value within said predefined bounded range 
using an appropriate algorithm for said monitored characteristic stored in memory. 

25 

The present invention thus obtains a value for the stress of a network, network 
object or part thereof within a predefined, bounded range, that is to say a "normalised" 
stress value. Since the stress value is a normalised value, is easy to understand, and 
requires no mterpretation by the network manager. 

30 
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Embodiments of the present invention will now be described, by way of example, 
with reference to the accompanying drawings, in which: 

Figure 1 is a block diagram of a typical network having a network management 
5 system according to a preferred embodiment of the present invention; 

Figure 2 is a stress mapping graph for a first stress metric which may be monitored 
by the network management system in accordance with the present invention; 

10 Figure 3 is a stress mapping graph for a second stress metric which may be 

monitored by the networic management system in accordance with the present invention; 
and 

Figure 4 is a flow chart showing the steps carried out by a computer program in 
1 5 accordance with a preferred embodiment of the present invention. 

Figure 1 shows a typical network 1 incorporating a network management system 
according to a preferred embodiment of the present invention. The network 1 includes 
a networic man^ement station 3A which incorporates the necessary hardware and 

20 software for network management. In particular, the network management station 
includes a processor, a memory and a di^ drive, and preferably also a modem for internet 
access, as well as user interfaces such as a keyboard and mouse, and a visual display unit. 
Network management application software in accordance with the present invention is 
loaded into the memory of management station 3 A for processing data as described in 

25 detail below. The networic management station 3 A is connected by network media Imks 
5 to a plurality of managed network devices including core devices such as network 
switch 7, hubs 1 1, a router (not shown) and end stations, which may be managed or 
unmanaged, including personal computers 3 and workstations. The network may also 
include unmanaged devices, for example peripheral devices such as printers etc. 



The network management station 3 A is capable of communicating with the 
managed network devices such as network switch 7 and hubs 1 1 by means of a network 
management protocol (e.g. the SNMP protocol) in order to obtain network management 
data. Each managed device includes a processor which monitors and stores data in 
memory on the device, and such data may be represented to an external management 
station by a MB (management information base), as is well known in the art, including 
data relating to inter alia data traffic at the device. A typical managed device monitors 
data contained in a number of MIBs, (of which one or more contains data used in the 
present invention). An example of aMIB containing network management data is MB-II 
(formerly MTO-I) as specified by the IETF (Internet Engineering Task Force) in 
specification RFC1213; MIB-II is common to most vendors' core devices and any 
network management system should preferably be capable of reading and utilising 
management data from Mffi-n. Furthermore, the network management system of the 
preferred embodiment of the present invention is additionally capable of reading and 
utilising more complex management data contained in such MIBs as RMON (Remote 
Monitoring MEB, RFC1271), RM0N2 (Remote Monitoring MB 2, RFC2021), the 
standard bridge MB (RFC1493), the standard repeater MB (RFC1516), or any 
propri^aiy MBs produced by original equipmeit manufecturers (e.g. the 3Com Remote 
PoUMB). 



In accordance with the preferred embodiment of the present invention, the 
network management station 3 A obtains data about a certain metric for a network object 
whidi is indicative of the level of "stress" of the network object. For example, the station 
3 A may request from a managed device, such as switch 7, a single piece of information 
(called an "object instance" or SmiP variable) from a MB about a particular state of the 
device such as the current error rate in data packets sent from and received at one of its 
ports. In accordance with the present invention, the data obtained from the MB is 
processed using a predetermined "moping algorithm" for error rate in a port of the 
switch to obtain a "normalised" stress value (as explained in more detail bdow). The 
normalised stress value may be displayed on the visual display unit of the network 
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management station or otherwise communicated to the network manager, e.g. via a 
printer or through another application such as a word processing application. The 
normalised stress value represents the perceived level of stress of the network device (i.e. 
a level which takes into account all relevant factors including the type and location of the 
5 network device) which can be readily imderstood by the network manager as indicating 
whether the level of stress is acceptable. 

The network management system may also obtain metric data for a network object 
without accessing a MIB in a managed device. For example, the network management 
10 station 3 A may send a signal to a device over a link which prompts a response from the 
device (e.g. by IP ICMP echo or IP Ping, as is known in the art). The networic 
management station will itself then monitor the time taken to receive a response from the 
device. The normalised stress value is then determined using a predetermined "mapping 
algorithm" for the monitored metric. 

15 

The followmg tables represent examples of the information/characteristics which 
the network management system, according to the preferred embodiment of the present 
invention, monitors. In the tables, the monitored information/characteristic is called a 
"metric" and the typical level of the raw measured value which represents an unacceptably 
20 high level of stress O-e. poor performance) is called the "defiuilt threshold" . The default 
threshold is set by the vendor of the network management system but may adjustable by 
the user, if required. 

Examples of metrics obtained by the network management station from a network 
25 device are shown in Table 1. These stress metrics are examples of characteristics 
monitored by the network management system to ensure that parts of the networic devices 
(i.e. discrete hardware or software components) are operating in an acceptable fashion. 



30 
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Table 1 





metric 


typical default threshold 




IP Ping response time 


1000 milliseconds 


5 


DNS response time 


1000 milliseconds 




FTP response time 


1000 milliseconds 




HTTP response time 


1000 milliseconds 




P0P3 response time 


1000 milliseconds 




SMTP response time 


1000 milliseconds 


10 


NFS response time 


1000 milliseconds 



(Note that not all devices will have all of the functions indicated by the metric. The 
network management station of the preferred embodiment only sends signals appropriate 
for each network device to obtain the metrics for that device). 

15 

Examples of metrics obtained by the network management station requesting 
information contained in a MEB m a managed network device such as switch 7 are shown 
in Table 2 These stress metrics are exan^)les of the characteristics monitored in a core 
device to determine whetiier errors and bottlenecks of data traflBc (due to 
20 excessive traffic) are occurring in the device. 



Table 2 





metric 


typical default threshold 


25 


frames discarded due to 


0 frames per second 




excessive delay 




frames discarded due to 


0 frames per second 




MTU exceeded 




frames discarded because 


0 frames per second 


30 


filtering uble full 






rate of topology changes 


0 per second 



(Note that the metrics listed in Table 2 are monitored and stored in most layer 2 switching 
devices such as bridges or switches.) 



Examples of metrics obtained by the network management station from a network 
device such as a half duplex Ethernet interface or port on a netwbrk device are shown in 
Table 3. These stress metrics are examples of characteristics monitored to identify 
problems occurring at the ports of network devices such as over-utilisation of the link 
cormected to the port. 

Tables 



metric 


typical default threshold 


link utilisation 


35% bandwidth 


link error rate 


S % all fi^es 


collisions 


20 per second 


broadcast frames 


3000 per second 



(Note that the metrics listed in Table 3 are monitored and stored for each port in most 
managed network devices which support a MIB capable of monitoring traffic flow on a 
port (e.g. MIB-n, RMON, repeater MIB, or a similar operating MIB).) 

Finally, an example of a metric obtained by the network management station 
requesting data from a managed network device which supports a proprietary MIB, for 
example a MIB of 3Com Corporation, is response time from far end of link, which has a 
typical de&uh threshold of 1 000 milliseconds. The network management station requests 
from the network device this data, and the processor in the network device sends a signal 
to the 6r end of the link and times the period for a response to be received. The 
monitored response time is then provided to the management station as a raw value 
intficative of problems relating to the speed of transmission of data across the network. 

A normalised stress value is determined by the network management system of the 
preferred embodiment using an appropriate algorithm as discussed in more detail below, 
based on a) the characteristics of the information being requested; b) the type of managed 
device being monitored, and c) the type of media to which the device is attached. In the 
embodiment, the stress value is "normalised" for all stress metrics within a predefined. 
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bounded range. In the preferred embodiment the range is 0-100 where 100 is an 
unacceptable level of stress. As mentioned previously, the stress value for each metric is 
determined using an appropriate "stress mapping" algorithm which considers the 
aforementioned factors a) to c) to provide an appropriate level of perceived stress in the 
range 0 to 100 to the user. In particular, the stress mapping applied to any monitored 
vahie will always return a stress value in the same range i.e. 0 to 100, The stress mapping 
algorithms for all monitored values (i.e. all metrics for all networic objects) are designed 
such that a given reported stress value always has the same meaning for the user, no 
matter which raw monitored value (i.e. metric) was used to gen^ate the stress value. A 
better understanding of the manner of implemenution of the stress mapping algorithms, 
which are predetermined by the vendor of the network management system, will be 
appreciated from Examples 1 and 2. 

Example 1 :First stress metric - Link utilisation 

The network management station 3A requests from the network switch 7 a 
numerical value (or object instance) in Mffi-H (and also in RMON) for determining the 
link utilisation at a particular port of the switch 7. As is well known in the art, the 
processor in switch 7 will monitor the numbers of data packets and bytes which are 
transmitted from and received at each of its ports and store this data in memory as an 
appropriate MIB. The network management station 3A receives the MLB data for a 
particular port and therefore the link connected to the port, and knowing: the type of link 
and its state of operation, and therefore its bandwidth; and, the elapsed time since the last 
request and the last requested value, and hence the traflSc rate since the last request; 
determines the % utilisation of the link. The % utilisation of bandwidth of the link is 
referred to below as the "utilisation value" and is a "raw value" (i.e. before stress 
mapping). 



30 



The network management station then compares the utilisation value with the 
default threshold for the link stored in its memory (e.g. 35% bandwidth in accordance 
with Table 3). If the utilisation value exceeds or equals the default threshold then the 
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unacceptably high level of stress. If the utilisation value is below the default threshold 
then the processor utilises an appropriate stress mapping algorithm to determine the stress 
value within the range 0 to 1 00 corresponding to the utilisation value. 

5 The relationship between the utilisation value and the perceived level of stress is 

non- linear. The stress mapping for link utilisation may be represented as shown in Figure 
2. As can be seen from this graph, the perceived stress on the network link increases 
dramatically from about 30% to an unacceptable level at 35% bandwidth utilised (the 
defeult threshold in Table 3). Thus 35% bandwidth utilisation or greater equates to the 

10 maximum stress value 100 as explained above. 

At levels bdow 3 5% bandwidthutilisation, the non-linear rdationship between link 
utilisation and percdved stress may be represented by key points as shown in Table 4. 

IS Table 4 



20 



25 



raw value 


stress (0 to lOO^ 


0 


0 


5 


1 


S 


2 


10 


5 


20 


10 


25 


20 


30 


30 


32 


50 


35 


100 



The implementation of the stress mapping algorithm extrapolates these key points 
to detennine the appropriate stress vahie between 0 and 100 for any raw value (utilisation 
30 value). 



Example 2:Second stress metric - Linlc error 
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The network management station 3 A requests from the network switch 7 the 
number of error frames received at a certain port and the number of data packets received 
at that port. This data is contained in a MIB of the switch 7 such as MIB-II, RMON, or 
a similar standard or proprietary MDB. As is well known in the art, the processor in 
5 switch 7 keeps a count of the number of data packets which are received at each of its 
ports, and the number of data packets recaved in error at each of its ports, and stores this 
data as an ^propriate MB. The network management station 3A receives the 
aforementioned MIB data for a particular port and knowing the elapsed time since the last 
request and the last requested values, determines the % data packets in error on the link. 
1 0 The % data packets m error on the link, i.e. the error rate, is referred to below as the 
"error value" and is a "raw value" (i.e. before stress mapping). 

The network management station then compares the error value with the default 
threshold for errors on the particular link stored in its memory (e.g. 5% frames in error 
15 in accordance with Table 3 ). If the error value exceeds or equals the default threshold 
then the stress value is determined to be the maximum stress value i.e. 100, indicatii^ an 
unacceptably high level of stress. If the error value is below the default threshold then the 
processor utilises an appropriate stress moping algorithm to determine the stress value 
within the range 0 to 100 corresponding to the error value. 

20 

The relationship between the error value the perceived level of stress is non- linear. 
The stress mapping for link error may be represented as shown in Figure 3. As can be 
seen frcm this graph, the perceived stress on the network Imk increases dramatically from 
about 4% error rate to an unacceptable levd at 5% frames in error (the defeult threshold 
25 in Table 3). Thus 5% error or greater equates to the maximum stress value of 100. 

At levels below 5% error, the non-linear relationship between % frames in error 
and perceived stress may be represented by key points as shown in Table 5. 



30 
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Table 5 



raw value 


stress ro to 100) 


0 


0 


1 


1 


2 


2 


3 


5 


4 


30 


5 


100 



The implementation of the stress mapping algorithm in the network management 
station extrapolates the key points in the stress mapping shown in Table 5 to obtain a 
stress vahie within the range 0 to 100 correq)onding to any raw value 0.e. error value). 

15 

In accordance with the preferred embodiment of the present invention, the 
network management station 3 A stores in memory the stress mapping algorithms and 
de&ult thresholds for all stress metrics monitored in the management system The 
processor of the network management station running the application software carries out 

20 the steps ^own in Hgure 4. At step 101 the program obtains for a particular network 
object a raw data value (or object instance) for a given metric and in step 102 compares 
it to the de&ult threshold If in step 103 it is found that the raw data value is greater than 
or equal to the default threshold, a de&uh condition arises whereby the processor 
determines that the stress value is a de&ult value in step 104, which in the preferred 

25 mibodiment is a maxnrnun (i.e. 100). Otherwise, the processor retrieves the appropriate 
algorithm for the metric in step 105 and calculates the normalised stress value (Le. 
between 0 and 100) in step 106. 

The thus determined stress value represents meaningfiil information to the network 
30 manager since it is norniahsed within a predetermined rax^e. If the normalised stress 
value is then sent to a display unit in step 1 07 to be displayed or to a printer to be printed 
e.g. as a number on the visual display unit of the network management station, together 
with a large number of other normalised stress values, the network manager can simply 
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look for high numbers (say above 50) to detect potential problems. Accordingly, by 
utilising "stress-mapping" to determine a normalised stress value for each metric of a 
network object, the network manager can compare the stress of different areas of a device 
or different parts of the network and be able to judge which areas need the most urgent 
attention, without the need to analyse the data for each device to determine whether it has 
a relatively high stress level for the type of device, the type of media link and the operating 
state of the link. 

The network management system in accordance with the preferred embodiment 
of the present invention is designed to monitor a plurality of different stress metrics for 
each network object. The system retrieves the monitored data for some or all of the 
metrics appropriate to a given network object and aggregates the data to form an overall 
object stress value as explained below. This enables the user to view the data for an 
individual network object and ascertain its overall performance. 

For instance, the stresses of a plurality of individual stress metrics of a network 
device are monitored and the data obtained is aggregated to form an overall device stress 
value. 

A networic device such as switch 7 is typically composed of the foUowing 
components: 

- a stackable baclqplane of some kind to which individual units (i.e. switches, 
routers etc) may be attached; 

- a bus within each unit into which blades can be inserted; and 

- ports or interfaces on each blade. 

The stress of these components may be aggregated together to provide an overall 
stress value for the network device. Similarly, the stress of mukiple network devices may 
be aggregated together to provide a single metric for overall network stress. 
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Example 3: Aggregation strategy for stress values for a plurality of metrics in a network 
device 

In this example, the aggregation strategy for a given network device such as 
switch 7 (which may be a stacked device formed from several units) is as follows: 

Step 1 : The stress of each blade is determined to be the worst of: 

- the blade' s own monitored stress (i.e. the stress derived using measurable metrics 
on the blade itself);and 

- the worst stress of any of the ports (or inter&ces) on that blade 

Step 2: The stress of each unit is determined to be the worst of: 
. the unit's own monitored stress; and 

- the worsT stress ofanyofthe blades inserted in that unit (as determined in Step 

1) 

Step 3 : The stress of each network device is determined to be the worst of: 

- the device's own monitored stress; and 

- the worst stress of any of the units ^ch are part of the device (as determined 
in Step 2) 

The overall stress of the network can then be determined, for example to be the 
worst of the stresses of all of the netwoik objects within the network. 

The overall stress of the network is thus the worst stress of any individual 
monitored component within the network. 

Example 4: Alternative aggregation strategies 



Other more advanced aggregation strategies may follow the strategy of Example 
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3, but with the following additions: 

1. For a unit or blade, also consider the effect that the bad performance of that 
component has on the parent component's ability to support other constituents. 

For example, a blade which is under high stress may affect the performance of 
other blades if it congests the common, shared backplane. A unit vAdch is under high 
stress may affect the performance of a networic device if it congests the device's single 
interface onto the networic 

2. For the network device, unit or blade, the stress of the component may be 
determined to be worse or better than just the worst of the constituent components. 

For example, the stresses of the interfaces on a blade may be 60, 70 and 80. But 
the network management system may intefligently decide that this combination of very 
hi^ stresses means that the blade itself is stressed to, say, 90. If the stresses were 10, 10 
and 80, the management appUcation may decide that this single high stress does not 
warrant a blade stress of 80, but perhaps only 50. 

As described above, in accordance with a preferred embodiment of the present 
invention, the netwo± management system monitors a plurality of stress metrics for all 
of the managed devices on the network, and in addition to aggregatii^ the data for each 
object (e.g. device) to form an overall stress value for that object (e.g. device), the 
network management system may additionally aggregate together the overall object stress 
values of all of the network objects to provide an overall stress value for the network. 
Alternatively, the network managemrat system may aggr^ate the worst of the underiying 
stresses of each of the devices, or at each network level, to provide the overall network 
stress values. In the latter case, the overall network stress value will represent the stress 
value of the least healthy device or component across the whole network. 



-17- 

The network management station in accordance with the invention may monitor 
stress periodically or in response to commands from the network manager. 

As will be appreciated from the foregoing, in accordance with a preferred 
5 embodiment, the present invention is implemented in the form of a software application 
which may be provided in the form of a computer program on a computer readable 
medium. The computer readable medium may be a disk which can be loaded in the disk 
drive of network management station 3 A or the computer system carrying the website or 
other form of file server (e.g. FTP) o^ for example, the supplier of network devices, 
10 which permits downloading of the program by a management station over the internet. 

The program steps 101 to 107 are illustrated in Hgure 4 and have been described 

above. 

IS As the skilled person will appreciate, various modifications may be made to the 

described embodiments and examples. For instance, as previoiisly mentioned, if the 
invention is applied to determine a health value in a netwoik, it will be appreciated that 
the same metrics, raw values and de&uh thresholds will be applicable as for stress, as 
described above. However, the mapping algorithms will dififer, and the defioilt threshold 

20 wiD return the minimum vahie within the normalised range indicating poor health. The 
network manager wiU then need to look for low values of health to detect potential 
problems in the n^ork. 

The present invention is intaided to include all such modifications and equivalents 
25 which M within the scope of the present invention as defined in the accompanying claims. 
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CLAIMS: 

1 . A method for processing data representing monitored characteristics in a network 
5 cotry)rising network devices and links to provide a stress value representing the 

performance of the network or a part thereof, the method comprising: 

obtaining a raw value of data for a monitored characteristic of a network device 

or link; 

comparing said raw value with a predetermined threshold value for said monitored 
10 characteristic; 

if said raw data vahie is greater than or equal to said threshold value, providing 
a stress value equal to a default vahie, said default value being a maximum or mmiTmini 
value of a predefined bounded range; and 

if said raw value is less than said threshold value, calculating a stress value within 
15 said predefined bounded range using an appropriate algorithm for said monitored 
characteristic. 

2. A method as claimed in claim 1, wherein said monitored characteristic relates to 
the port of a network device and concerns the utilisation of the link connected to the 

20 device. 

3. A method as claimed in claim 2, wherein said monitored characteristic includes 
one of: link utilisation in fi^es per second; link error rate in fi^es per second; collisions 
per second, and broadcast fi^mes per second. 

25 

4. A method as claimed in claim 1, 2 or 3, wherein said step of obtaining a raw value 
comprises receiving said raw value fi-om memory in a network device. 



30 



5. A method as claimed in claim 1, 2 or 3, wherein said step of obtaining a raw value 
comprises receiving data values firom memory in a network device, and calculating said 
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raw value for said monitored characteristic using said data values. 

6. A method as claimed in claim 1, wherein said monitored characteristic relates to 
the operating speed of hardware within a network device. 

7. A method as claimed in claim 6, wherdn said monitored characteristic includes 
one of: IP Ping response time; DNS response time: FTP response time; HTTP response 
time; P0P3 response time; SMTP response time, and NFS response time. 

8. A method as claimed in claim 6 or claim 7, wherein said step of obtaining a raw 
value comprises: 

sending a signal to said hardware in said network device, which signal prompts a 
response from said hardware, and 

timing the period for the response to be received; 
wherein said timed time period is the raw vahie. 

9. A method as claimed in claim 1, wherein said monitored characteristic is a 
diaracteristic relating to errors occurring in a core networic device. 

10. A method as claimed in daim 9, who'ein said monitored characteristic includes 
one of: frames per second discarded due to excessive delay; frames per second discarded 
due to MTU exceeded; frames per second discarded because fiiterii^ table is full, and 
rate of topology changes. 

11. A method as claimed in claim 9 or claim 10, wherein said step of obtaining a raw 
value comprises receiving said raw value from memory in said core network device. 

12. A method as claimed in any preceding claim, wherein said predefined bounded 
range is 0 to 100, where the default value is 100 if it is the maximum value and 0 if it is 
the minimum value. 
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13. A method as claimed in any preceding claim, further comprising displaying said 
stress value as alphanumeric text or in graphical form on a display screen. 



14. A method as claimed in any preceding claim, wherein the threshold value for the 
5 monitored characteristic is adjustable by the user. 

15. A method for processing data representing monitored characteristics in a network 
comprising network devices and links to provide a stress value representing the 
performance of the network, the method comprising: 

10 obtaining a plurality of raw values of data for a corresponding plurality of 

monitored characteristics of a network device or link; 

comparing each raw value with a predetermined threshold value for said 
corresponding monitored characteristic; 

for each raw value determining a stress value within a predetermined bounded 

15 range of values, wherein if said raw data value is greater than or equal to said 
corresponding threshold value, determining a stress value equal to a defeuk value, said 
defeult value being either the maximum or minmium value of said predefined bounded 
range; and if said raw value is less than said threshold value, calculating a stress value 
within said predefined bounded range using an appropriate algorithm for said monitored 

20 characteristic. 

16. A method as claimed in claim 15, fiirther compri^ng aggregating the stress values 
obtained for each of said plurality of monitored characteristics to provide an aggr^ted 
stress value. 

25 

17. A method for processing data representing monitored characteristics in a network 
comprising network devices and links to provide a stress value representing the 
performance of the network substantially as hereinbefore described, with reference to the 
accompanying drawings. 

30 
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18. A computer readable medium containing a computer program for carrying out the 
method as claimed in any preceding claim. 

19. Apparatus for processing data representing monitored characteristics in a network 
5 comprising network devices and links to provide a stress value representing the 

performance of the network, the apparatus comprising: 

a network connection or port for receiving a raw value of data for a monitored 
characteristic of a network device or link; 

a processor for comparing said raw value with a predetermined threshold value 

1 0 for said monitored characteristic obtained fix>m memory; and if the conq)arison determines 
that raw data value is greater than or equal to said threshold value, providing a stress 
vahjeequaltoade&uhvahie, saidde&ukvahiebdnga maxmium or minimum value of 
a predefined bounded range; and if the comparison detennines that said raw value is less 
than said threshold vahie, calculating a stress value within said predefined bounded range 

1 S using an appropriate algorithm for said monitored characteristic stored in memory. 

20. ^paratus as claimed in claim 1 9, wha^ said monitored characteristic relates to 
the port of a network device and concerns the utilisation of the link connected to the 
device. 

20 

2 1 . Apparatus as claimed in claim 20, wherein said monitored characteristic indudes 
one of: link iitilisation in firames per second; link error rate in fiames per second; collisions 
per second, and broadcast fi^es p^ second. 

25 22. Apparatus as claimed in claim 19, 20 or 21, wherein said apparatus obtains said 
raw value by receiving said raw value at said port fi^om memory in a networic device. 

23. Apparatus as claimed in claim 19, 20 or 21, wherein said apparatus obtains said 
raw value by receiving data values at said port fi'om memory in a network device, and said 
30 processor calculating said raw value for said monitored characteristic using said received 



data values. 



24. Apparatus as claimed in claim 1 9, wherein said monitored characteristic relates to 
the operating speed of hardware within a network device. 

5 

25. Apparatus as claimed in daim 24, wherein said monitored characteristic includes 
one of: IP Ping response time; DNS response time: FTP response time; HTTP response 
time; POPS response time; SMTP response time, and NFS response time. 

1 0 26. Apparatus as claimed in claim 25 or claim 26, \^4ierein said apparatus obtains said 
raw value by sending a signal to said hardware in said network device, which signal 
prompts a response from said hardware, and timing the period for the response to be 
received; wherein said timed time period is the raw value used by said processor. 

15 27. Apparatus as claimed in daim 19, wherein said monitored characteristic is a 
characteristic relating to OTors occurring in a core network device. 

28. Apparatus as claimed in claim 27, wherein said monitored characteristic includes 
one of: frames per second discarded due to excessive delay; fi^es per second discarded 

20 due to MTU exceeded; frames per second discarded because filtering table is full, and 
rate of topology changes. 

29. Apparatus as claimed in daim 27 or claim 28, wherein said apparatus obtains said 
raw value by receiving said raw value at said port from memory in said core network 

25 device. 

30. Apparatus as claimed in claim 27 or claim 28, wherein said apparatus obtains said 
raw value by receiving data values at said port from memory in a network device, and said 
processor calculating said raw value for said monitored characteristic using said received 

30 data values. 
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31. ^paratus as claimed in any one of claims 19 to 30, wherein said predefined 
bounded range is 0 to 100, where the default value is 100 if it is the maximum value and 
0 if it is the minimum value. 

32. Apparatus as claimed in any one of clainisl9 to 3 1, further comprising a display 
for receiving said stress value from said processor and displaying said stress value as 
alphanimtieric text or in graphical form. 

33. Apparatus as claimed in any one of claims 19 to 32, further comprising memory 
to store said predetermined threshold value. 

34. Apparatus as claimed in claim 33, further compnsmg means for writing a threshold 
value for a monitored characteristic to said memory. 

35. Apparatus as daimed in any one of claims 19 to 34, wherein said apparatus is 
capable of obtaining a plurality of raw values of data for a corresponding plurality of 
monitored characteristics of a networic device or link at said port, and said processor is 
adapted to compare each raw value with a predetermined threshold value for said 
corresponding monitored characteristic retrieved from memory, and for each raw value 
determining a stress value within a predetermined bounded range of values, wherein if said 
raw data value is greater than or equal to said corresponding tfare^old value, detenninii^ 
a stress value equal to a default value, the defriult value being either a maximum or 
tniimmifn value of Said predefined bounded range; and if said raw value is less than said 
threshold value, calculatii^ a stress value within said predefined bounded raiige using an 
appropriate algorithm for said monitored characteristic, the processor thereby providing 
a plurality of stress values corresponding to said plurality of raw values,. 

36. Apparatus as claimed in claim 35, wherein said processor if fiirther adapted to 
aggregate the plurality of stress values for each of said plurality of monitored 
characteristics to provide an aggregated stress value. 
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37. Apparatus substantially as hereinbefore described with reference to, and as shown 
in, the accompanying drawings. 

V 
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